Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function in admin.class.php component.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://www.bosscms.net/ | product |
https://github.com/n0Sleeper/bosscmsVuln/issues/1 | third party advisory exploit |
https://github.com/n0Sleeper/bosscmsVuln | third party advisory |